Arbitrary Code Execution Vulnerability in Zed IDE by Zed Industries
CVE-2025-68432

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
17 December 2025

What is CVE-2025-68432?

The Zed IDE, a popular code editor, contains a vulnerability that allows for arbitrary code execution through manipulated Language Server Protocol (LSP) configurations. If a user unwittingly opens a project containing a malicious settings.json file located in the project's .zed subdirectory, an attacker could execute arbitrary shell commands with the user's privileges. The vulnerability is triggered when the IDE loads these configurations upon opening the project file. To mitigate this risk, version 0.218.2-pre introduces a worktree trust mechanism, while users are advised to thoroughly examine the contents of any project settings file before opening projects in Zed.

Affected Version(s)

zed < 0.218.2-pre

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-68432 : Arbitrary Code Execution Vulnerability in Zed IDE by Zed Industries